First published: Mon Jun 03 2024(Updated: )
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flowplayer Video Player | <=7.5.45.7212 | |
Flowplayer Video Player | <=7.5.45.7212 |
Update to 7.5.46.7212 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35631 is considered a critical vulnerability due to its potential for reflected Cross-site Scripting (XSS) attacks.
To fix CVE-2024-35631, update the FV Flowplayer Video Player to version 7.5.45.7213 or later.
CVE-2024-35631 affects FV Flowplayer Video Player versions up to and including 7.5.45.7212.
CVE-2024-35631 represents an Improper Neutralization of Input During Web Page Generation, categorized as a Cross-site Scripting (XSS) vulnerability.
Yes, an attacker can exploit CVE-2024-35631 to execute malicious scripts in the context of the victim's session.